<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<title>P256 - Sicherheit 2016 - Sicherheit, Schutz und Zuverlässigkeit</title>
<link>http://dl.gi.de/handle/20.500.12116/20073</link>
<description/>
<pubDate>Wed, 22 Jul 2026 18:52:16 GMT</pubDate>
<dc:date>2026-07-22T18:52:16Z</dc:date>
<image>
<title>P256 - Sicherheit 2016 - Sicherheit, Schutz und Zuverlässigkeit</title>
<url>http://dl.gi.de:80/bitstream/id/9894bf84-ccb0-4815-84c5-16141b54c47d/</url>
<link>http://dl.gi.de/handle/20.500.12116/20073</link>
</image>
<item>
<title>Automotive Ethernet: security opportunity or challenge?</title>
<link>http://dl.gi.de/handle/20.500.12116/880</link>
<description>Automotive Ethernet: security opportunity or challenge?
Corbett, Christopher; Schoch, Elmar; Kargl, Frank; Preussner, Felix
Meier, Michael; Reinhardt, Delphine; Wendzel, Steffen
The automotive industry's future trends, such as automated driving or advanced driver assistance, require large bandwidths to handle massive data streams and strongly depend on well timed communication. The Ethernet technology is seen as a suitable candidate to cover those needs for vehicle-internal networks; however, Ethernet involves security issues. Thus, by discussing automotive Ethernet attributes with regard to the adaption of existing security mechanisms in contrast to the potential of creating new ones, several challenges and opportunities emerge in consideration of comparatively fewer available resources and the integration into a vehicle environment. Based on these results we derive and propose ideas for manipulation and misuse detection mechanisms.
</description>
<pubDate>Fri, 01 Jan 2016 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/880</guid>
<dc:date>2016-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>Surreptitious sharing on android</title>
<link>http://dl.gi.de/handle/20.500.12116/882</link>
<description>Surreptitious sharing on android
Schürmann, Dominik; Wolf, Lars
Meier, Michael; Reinhardt, Delphine; Wendzel, Steffen
Many email and messaging applications on Android utilize the Intent API for sharing images, videos, and documents. Android standardizes Intents for sending and Intent Filters for receiving content. Instead of sending entire files, such as videos, via this API, only URIs are exchanged pointing to the actual storage position. In this paper we evaluate applications regarding a security vulnerability allowing privilege escalation and data leakage, which is related to the handling of URIs using the file scheme. We analyze a vulnerability called Surreptitious Sharing and present two scenarios showing how it can be exploited in practice. Based on these scenarios, 4 email and 8 messaging applications have been analyzed in detail. We found that 8 out of 12 applications are vulnerable. Guidelines how to properly handle file access on Android and a fix for the discussed vulnerability are attached.
</description>
<pubDate>Fri, 01 Jan 2016 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/882</guid>
<dc:date>2016-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>SDN malware: problems of current protection systems and potential countermeasures</title>
<link>http://dl.gi.de/handle/20.500.12116/884</link>
<description>SDN malware: problems of current protection systems and potential countermeasures
Röpke, Christian
Meier, Michael; Reinhardt, Delphine; Wendzel, Steffen
Software-Defined Networking (SDN) is an emerging topic and securing its data and control plane is of great importance. The main goal of malicious SDN applications would be to compromise the SDN controller which is responsible for managing the SDN-based network. In this paper, we discuss two existent mechanisms aiming at protecting aforementioned planes: (i) sandboxing of SDN applications and (ii) checking for network invariants. We argue that both fail in case of sophisticated malicious SDN applications such as a SDN rootkit. To fill the corresponding security gaps, we propose two security improvements. The first one aims at protecting the control plane by isolating SDN applications by means of virtualization techniques. Compared to recent efforts, we thereby allow a more stringent separation of malicious SDN applications. The goal of the second proposal is to allow policy checking mechanisms to run independently from SDN controllers while minimizing hardware costs. Thereby, we improve SDN security while taking into account that correct functioning of policy checking can be manipulated by a compromised SDN controller.
</description>
<pubDate>Fri, 01 Jan 2016 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/884</guid>
<dc:date>2016-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>Distributed evolutionary fuzzing with evofuzz</title>
<link>http://dl.gi.de/handle/20.500.12116/878</link>
<description>Distributed evolutionary fuzzing with evofuzz
Beterke, Fabian
Meier, Michael; Reinhardt, Delphine; Wendzel, Steffen
This paper describes the design of a tool (called Evofuzz) that implements the technique of evolutionary (or coverage-guided) fuzzing in a scalable, distributed manner. The architecture, design-choices and implementation specifics of this tool are examined, explained and criticized. After outlining possible improvements and future work that is not yet completed, the paper finishes by presenting the results from fuzzing real-world programs and explains how to recreate them using the provided tool.
</description>
<pubDate>Fri, 01 Jan 2016 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/878</guid>
<dc:date>2016-01-01T00:00:00Z</dc:date>
</item>
</channel>
</rss>
